⋆˚˖。꩜⭒˚.⋆

Joined June 2007
2 Photos and videos
Wie sich Linke das Vermögen von Elon Musk vorstellen:
149
550
17,971
530,878
t retweeted
the level of greed is inspirational
18
930
8,751
200,156
Deutschland: TV-Zwangsgebühren 220€ WM Eröffnungsfeier zensiert. 60 Spiele in 720p. - 480p. Match HD Brasilien: Keine Zwangsgebühren 104 Spiele komplett in 4K kostenlos Türkei: Keine Zwangsgebühren Alle 104 WM-Spiele frei Ungarn: Keine Zwangsgebühren Alle 104 WM-Spiele frei
70
194
2,298
103,199
t retweeted
95
999
9,593
829,325
t retweeted
At the eye clinic
54
6,057
44,789
616,488
Veni wurde auseinander genommen!? x.com/i_burgerin/status/2057…

76
75
2,652
348,624
May 6
🗣️ #WirVerlassenX - Aber X Premium darf man ja wohl noch haben dürfen...
1
3
390
t retweeted
Unter #WirVerlassenX verlassen Grüne, Linke und SPD das Schlachtfeld. Ein Zeichen für "Wir geben auf, wenn es unangenehm wird". Und ein Geschenk an die Gegner. Denn es bleibt hängen: "Man kann die Linksgrünen besiegen, schaut her!" Gratis-Motivation und Siegestaumel inklusive.
43
74
880
13,185
t retweeted
︎ ︎ ︎ ︎ ︎ ︎ ︎ Privacy is not negotiable. ︎ ︎ ︎ ︎ ︎ ︎ ︎ ︎
77
602
4,300
91,056
Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..." I did. It didn't take long to find what looks like a serious #privacy issue. The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well. But, the source image used to collect that data is written to disk without encryption and not deleted correctly. For NFC biometric data: It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them. For selfie pictures: Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them. This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary. From a #GDPR standpoint: Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach. youtube.com/watch?v=4VRRriyD…
656
6,065
24,319
3,390,228
8
783
12,723
192,099
t retweeted
11
486
5,771
93,633
t retweeted
Minecraft 3D generation now at the highest quality ever, built using @fal ⛏️ Text → Image (nano-banana-pro) → 3D mesh (Hunyuan 3D v3.1) → Voxelize → Texture mapping → Minecraft structure!
103
108
2,633
490,839
t retweeted
Der Krieg muss jetzt enden
9
11
695
17,467
t retweeted
Mar 23
Replying to @IronIntOfficial
Nah man
23
19
2,452
41,227
t retweeted
14
159
4,266
162,157
21
1,053
17,226
269,606
t retweeted
Habe ich das richtig verstanden, für „Misgendern“ linker Politiker: 10.000 Euro Strafe – aber ein linker Politiker mit 4.000 Kinderpornodateien auf dem Laptop kommt mit 1.000 Euro davon?
104
866
5,926
65,918
t retweeted
11
559
5,400
76,012
t retweeted
59
2,794
79,330
694,142